GDPR — EU Reg. 2016/679

Privacy Policy

Last updated: May 2026

Plan Trip is a travel planning web app. Your travel data is stored exclusively on your device (browser localStorage) and is never transmitted to the app's own servers. The only external transmissions occur if you choose to enable Google Drive synchronisation and/or real-time collaboration via Firebase.

1 Data Controller

Jacopo Conti
Email: plan.trip.support@gmail.com

2 Data processed and purposes

2.1 Data saved locally (only on your device)

Plan Trip saves in your browser's localStorage the following data, which remains exclusively on your device and is never sent to our servers:

DataPurposeLegal basis
Trip names and datesItinerary managementArt. 6.1.b GDPR
Itinerary content (cities, accommodations, activities, prices, links)Trip planningArt. 6.1.b GDPR
Theme preference (light/dark)Interface personalisationArt. 6.1.f GDPR
Language preference (Italian/English)Interface personalisationArt. 6.1.f GDPR

You can delete this data via: Browser developer tools → Application → Local Storage.

2.2 Data processed with Google Drive sync (optional)

The synchronisation feature is completely optional and requires your explicit consent via Google account sign-in.

DataSourceWhere storedPurpose
Google email addressGoogle OAuth2localStorage (your device only)Account display
Google display nameGoogle OAuth2localStorage (your device only)Account display
OAuth2 access tokenGoogle Identity ServiceslocalStorage (expires ~1 hour)Drive API authentication
Itinerary contentUser inputGoogle Drive (private app folder)Backup and cross-device sync

Sync data is in appDataFolder, accessible only by Plan Trip. To revoke access: myaccount.google.com/permissions.

2.3 Data processed with trip sharing (optional)

If you choose to share a trip via link, the app saves a copy of the trip in your regular Google Drive ("Plan-Trip" folder, visible in your Drive) and sets public read permissions to allow access to anyone with the link.

DataWhere storedWho can accessPurpose
Full itinerary copy (JSON)Google Drive ("Plan-Trip" folder)Anyone with the link (read only)Trip sharing

Shared files can be deleted from your Google Drive at any time.

2.4 Data processed with real-time collaboration (optional)

If you enable collaboration, trip data is synchronised in real time via Firebase Firestore (Google Cloud). Authentication is handled by Firebase Authentication using your Google account.

DataSourceWhere storedPurpose
Google UID, email and nameFirebase AuthenticationFirebase Auth + FirestoreCollaborator identification
Full itinerary dataUser inputFirebase FirestoreReal-time synchronisation
Lock state (who is editing)Generated by the appFirebase FirestoreEdit conflict prevention
Collaborator emailsEntered by the ownerFirebase FirestoreAccess control

Firestore data can be removed by stopping collaboration from the sharing panel.

3 Third-party services

3.1 CARTO (maps)

Interactive maps use CARTO (basemaps.cartocdn.com). When you view a map, your browser transmits your IP and the viewed region to CARTO.

Privacy: carto.com/privacy

3.2 Google Maps (external links)

Some cards display links to Google Maps. Clicking is voluntary and triggers data transmission to Google under their own terms.

3.3 Google (auth and Drive)

If you enable sync, Google scripts are loaded from accounts.google.com and apis.google.com. Google processes data under their own privacy policy: policies.google.com/privacy.

3.4 Firebase (real-time collaboration)

If you enable collaboration, Firebase scripts are loaded from firebaseio.com and googleapis.com. Firebase is a Google Cloud service and data is processed under Google's privacy policy: firebase.google.com/support/privacy.

4 International transfers

Google LLC (USA), including Firebase, is covered by the EU–US Data Privacy Framework (EU adequacy decision, 10 July 2023). CARTO uses datacentres in the European Union.

5 Retention period

DataRetention
Itinerary data (localStorage)Until voluntary deletion or browser clearing
Google email and nameUntil explicit logout from the app
Google access token~1 hour (technical expiry), renewed if logged in
Data on Google DriveUntil deletion from the cloud panel or access revocation
Data on Firebase FirestoreUntil collaboration is stopped or the trip is deleted

6 Your rights (GDPR Art. 15–22)

Access
Request a copy of your personal data
Rectification
Correct inaccurate data
Erasure
Right to be forgotten — request deletion
Portability
Receive data in a structured format (JSON export available)
Objection
Object to processing based on legitimate interest
Withdraw consent
At any time, without affecting prior processing

Contact: plan.trip.support@gmail.com

You may lodge a complaint with your national data protection authority.

7 Security

All data remains on your device and does not pass through the app's own servers. Communication with Google Drive and Firebase uses HTTPS with OAuth2 authentication exclusively. We do not store passwords.

8 Policy changes

Any changes will be communicated by updating the date at the top of this page. Continued use of the app after changes constitutes acceptance of the updated policy.

9 Cookie Policy

For information on cookies see our Cookie Policy.